ComboFix 08-07-19.1 - AHMED AL NAJJAR 2008-07-21 9:38:55.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.974.1033.18.83 [GMT 3:00]
Running from: C:\Documents and Settings\AHMED AL NAJJAR\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-06-21 to 2008-07-21 )))))))))))))))))))))))))))))))
.
2008-07-19 19:40 . 2008-07-19 19:40 <DIR> d-------- C:\Program Files\IObit
2008-07-19 19:36 . 2008-07-19 19:36 <DIR> d-------- C:\silver
2008-07-19 15:21 . 2008-07-19 15:21 <DIR> d-------- C:\Documents and Settings\AHMED AL NAJJAR\Application Data\CyberScrub
2008-07-19 15:20 . 2008-07-19 16:38 <DIR> d-------- C:\Documents and Settings\AHMED AL NAJJAR\Application Data\cleaner
2008-07-19 14:44 . 2008-07-19 14:44 <DIR> d-------- C:\QUARANTINE
2008-07-19 14:43 . 2008-07-19 14:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-07-19 14:42 . 2008-07-19 14:42 <DIR> d-------- C:\zxz23
2008-07-19 14:29 . 2008-07-19 14:29 2,508 --a------ C:\WINDOWS\system32\tmp.reg
2008-07-19 11:25 . 2008-07-19 11:29 <DIR> d-------- C:\Documents and Settings\AHMED AL NAJJAR\Pavark
2008-07-19 00:12 . 2008-07-21 09:41 121,690,144 --a------ C:\WINDOWS\system32\drivers\fidbox.dat
2008-07-19 00:12 . 2008-07-19 20:33 723,572 --a------ C:\WINDOWS\system32\drivers\fidbox.idx
2008-07-18 16:25 . 2008-07-18 13:25 138,240 --a------ C:\WINDOWS\system32\cime.exe
2008-07-18 16:16 . 2008-07-18 16:20 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-18 15:59 . 2008-07-18 15:59 <DIR> d-------- C:\Documents and Settings\AHMED AL NAJJAR\Application Data\TrojanHunter
2008-07-18 14:16 . 2008-07-18 14:16 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Avira
2008-07-18 13:16 . 2008-07-18 13:25 138,240 --a------ C:\WINDOWS\system32\koovedi.exe
2008-07-17 16:02 . 2008-07-17 16:02 <DIR> d-------- C:\Program Files\WinImage
2008-07-17 16:02 . 2005-10-16 08:00 12,928 --a------ C:\WINDOWS\system32\drivers\filedisk.sys
2008-07-15 23:16 . 2008-07-15 23:16 268 --ah----- C:\sqmdata07.sqm
2008-07-15 23:16 . 2008-07-15 23:16 244 --ah----- C:\sqmnoopt07.sqm
2008-07-15 23:16 . 2008-07-15 23:16 172 --ah----- C:\sqmnoopt08.sqm
2008-07-15 23:16 . 2008-07-15 23:16 172 --ah----- C:\sqmdata08.sqm
2008-07-14 13:49 . 2008-07-14 13:49 <DIR> d-------- C:\Documents and Settings\AHMED AL NAJJAR\Application Data\Thinstall
2008-07-14 13:17 . 2008-07-15 13:05 <DIR> d-------- C:\Program Files\Internet Download Manager
2008-07-14 11:58 . 2008-07-16 14:08 <DIR> d-------- C:\Documents and Settings\AHMED AL NAJJAR\Application Data\IDM
2008-06-30 18:44 . 2008-06-30 18:44 <DIR> d-------- C:\Program Files\iPod
2008-06-30 18:43 . 2008-06-30 18:44 <DIR> d-------- C:\Program Files\iTunes
2008-06-30 18:40 . 2008-06-30 18:42 <DIR> d-------- C:\Program Files\QuickTime
2008-06-30 18:15 . 2008-06-30 18:15 <DIR> d-------- C:\Program Files\Apple Software Update
2008-06-27 13:34 . 2006-05-13 21:29 843 --a------ C:\ChangeWinXPKey.vbs
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-21 06:37 --------- d-----w C:\Documents and Settings\AHMED AL NAJJAR\Application Data\DMCache
2008-07-20 15:34 --------- d-----w C:\Program Files\LowRateVoip
2008-07-20 11:23 --------- d-----w C:\Program Files\TuneUp Utilities 2007
2008-07-18 06:33 --------- d-----w C:\Program Files\Real_SC
2008-07-16 14:51 --------- d-----w C:\Documents and Settings\AHMED AL NAJJAR\Application Data\InterVoip
2008-07-14 10:30 --------- d-----w C:\Program Files\Download Direct
2008-07-11 20:27 --------- d-----w C:\Documents and Settings\AHMED AL NAJJAR\Application Data\Nuotex
2008-06-19 23:52 --------- d-----w C:\Program Files\Nokia
2008-06-19 22:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\zyz Kaspersky Lab setup files
2008-06-18 19:52 --------- d-----w C:\Documents and Settings\AHMED AL NAJJAR\Application Data\Avira
2008-06-18 17:58 --------- d-----w C:\Program Files\MSN Messenger
2008-06-18 17:04 71,592 ----a-w C:\WINDOWS\system32\drivers\avfwot.sys
2008-06-18 17:04 71,464 ----a-w C:\WINDOWS\system32\drivers\avfwim.sys
2008-06-18 16:57 --------- d-----w C:\Program Files\Avira
2008-06-18 16:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-06-13 10:15 --------- d-----w C:\Program Files\InterVoip.com
2008-06-12 21:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-06-11 20:43 --------- d-----w C:\Program Files\PasswordTools
2008-06-11 20:41 --------- d-----w C:\Program Files\AtomPark
2008-06-10 16:00 --------- d-----w C:\Program Files\SopCast
2008-06-06 15:20 --------- d-----w C:\Documents and Settings\AHMED AL NAJJAR\Application Data\ADPHONE
2008-05-28 20:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\BufferZone
2008-05-28 12:22 --------- d-----w C:\Documents and Settings\AHMED AL NAJJAR\Application Data\GibbHill Properties Ltd
2008-05-26 16:54 286,720 ------w C:\WINDOWS\iun506.exe
2008-05-26 16:54 --------- d-----w C:\Program Files\Application X
2008-05-24 10:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avg8
2008-05-23 18:18 --------- d-----w C:\Program Files\NightMare
2008-05-23 08:22 --------- d-----w C:\Program Files\HTV
2008-05-22 17:53 --------- d-----w C:\Documents and Settings\AHMED AL NAJJAR\Application Data\AVGTOOLBAR
2008-04-18 18:00 12,840 ------w C:\Documents and Settings\AHMED AL NAJJAR\bpkch.dat
2007-05-06 00:30 36,488 ------w C:\Documents and Settings\AHMED AL NAJJAR\bpk.dat
2007-05-06 00:25 36,363 ------w C:\Documents and Settings\AHMED AL NAJJAR\web.dat
2004-09-30 22:52 71,168 ------w C:\Documents and Settings\AHMED AL NAJJAR\cr_acds70.exe
.
((((((((((((((((((((((((((((( snapshot@2008-07-19_14.13.40.87 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-11 23:41:11 335,464 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-07-20 11:10:15 334,664 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
- 2008-07-19 08:20:40 63,188 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-07-20 11:18:42 63,188 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-07-19 08:20:40 403,968 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-07-20 11:18:43 403,968 ----a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 03:12 15360]
"LowRateVoip"="C:\Program Files\LowRateVoip\LowRateVoip.exe" [2008-01-26 14:11 8897848]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-22 18:47 68856]
"ares"="C:\Program Files\Ares\Ares.exe" [2007-07-17 00:54 961536]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2008-04-01 18:35 3587120]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2008-03-28 11:20 1079296]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe" [2008-03-26 18:41 1232896]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2008-05-08 15:12 5724184]
"InterVoip"="C:\Program Files\InterVoip.com\InterVoip\InterVoip.exe" [2008-05-29 09:39 8881456]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2008-07-15 13:05 932864]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-08-30 17:43 4670704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-12-01 11:32 185896]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"avgnt"="C:\Program Files\Avira\Avira Premium Security Suite\avgnt.exe" [2008-07-18 09:37 266497]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-06-02 11:13 267048]
"wougup"="C:\WINDOWS\system32\koovedi.exe" [2008-07-18 13:25 138240]
"SoundMan"="SOUNDMAN.EXE" [2005-02-23 13:13 77824 C:\WINDOWS\SOUNDMAN.EXE]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"wougup"="C:\WINDOWS\system32\koovedi.exe" [2008-07-18 13:25 138240]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 03:12 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2008-03-26 18:41 1232896]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Antiwpa]
2006-07-22 23:49 5376 C:\WINDOWS\system32\antiwpa.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DfLogon]
2004-04-13 17:02 49152 C:\WINDOWS\system32\LogonDll.dll
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\(Default)
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ares"="C:\Program Files\Ares\Ares.exe" -h
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
"YSearchProtection"=C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
"SweetIM"=C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe"
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
"Norton Ghost 9.0"=C:\Program Files\Symantec\Norton Ghost\Agent\GhostTray.exe
"SweetIM"=C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\LowRateVoip\\LowRateVoip.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Ares\\Ares.exe"=
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"C:\\Program Files\\SopCast\\SopCast.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\InterVoip.com\\InterVoip\\InterVoip.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R0 DeepFrz;DeepFrz;C:\WINDOWS\system32\drivers\DeepFrz.sys [2004-04-13 16:55]
R0 PQV2i;PQV2i;C:\WINDOWS\system32\drivers\PQV2i.sys [2004-07-29 03:33]
R1 avfwot;avfwot;C:\WINDOWS\system32\DRIVERS\avfwot.sys [2008-06-18 20:04]
R1 PQIMount;PQIMount;C:\WINDOWS\system32\drivers\PQIMount.sys [2004-07-29 04:13]
R2 AntiVirFirewallService;Avira Premium Security Suite Firewall;C:\Program Files\Avira\Avira Premium Security Suite\avfwsvc.exe [2008-07-18 09:37]
R2 AntiVirMailService;Avira Premium Security Suite MailGuard;C:\Program Files\Avira\Avira Premium Security Suite\avmailc.exe [2008-07-18 09:37]
R2 antivirwebservice;Avira Premium Security Suite WebGuard;C:\Program Files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE [2008-07-18 09:37]
R2 AVEService;Avira Premium Security Suite MailGuard helper service;C:\Program Files\Avira\Avira Premium Security Suite\avesvc.exe [2008-07-18 09:37]
R3 avfwim;AvFw Packet Filter Miniport;C:\WINDOWS\system32\DRIVERS\avfwim.sys [2008-06-18 20:04]
R4 is-BP03Edrv;is-BP03Edrv;C:\WINDOWS\system32\drivers\
06933587.sys []
S2 auiog8yx6xkhw;PowerUtility TV Recording Reservation;C:\WINDOWS\system32\cuvago.exe []
S2 iupcac5ywi2e6a7a;Crypkey License;C:\WINDOWS\system32\cime.exe [2008-07-18 13:25]
S2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2008-04-14 03:12]
S3 alcan5ln;SpeedTouch(tm) USB ADSL RFC1483 Networking Driver (NDIS);C:\WINDOWS\system32\DRIVERS\alcan5ln.sys [2003-12-08 11:53]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2008-02-01 15:17]
S3 nmwcdnsuc;Nokia USB Flashing Generic;C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2008-02-01 15:17]
S3 V0090VID;Creative WebCam Vista Plus;C:\WINDOWS\system32\DRIVERS\V0090Vid.sys [2005-04-14 04:00]
.
s of the 'Scheduled Tasks' folder
"2008-07-18 16:59:47 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2008-07-10 09:33:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-07-21 09:41:40
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\LogonDll.dll
.
Completion time: 2008-07-21 9:43:57
ComboFix-quarantined-files.txt 2008-07-21 06:43:48
ComboFix2.txt 2008-07-19 11:14:23
Pre-Run: 22,752,235,520 bytes free
Post-Run: 22,756,470,784 bytes free
205 --- E O F --- 2008-01-23 11:04:25